|
|
|
|
|
by stouset
645 days ago
|
|
> Our basic philosophy when it comes to security is that we can trust our developers and that we can trust the private network within the cluster. As an infosec guy, I hate to say it but this is IMO very misguided. Insider attacks and external attacks are often indistinguishable because attackers are happy to steal developer credentials or infect their laptops with malware. Same with trusting the private network. That’s fine and dandy until attackers are in your network, and now they have free rein because you assumed you could keep the bad people outside the walls protecting your soft, squishy insides. |
|